全网唯一标准王
ISO INTERNATIONAL STANDARD 28001 First edition 2007-10-15 Security management systems for the supply chain Best practices for implementing supply chain security, assessments and plans Requirements and guidance Systemes de management de la surete pour la chaine d'approvisionnement- -Meilleures pratiques pourla mise en application de la surete de la chaine d'approvisionnement, évaluations et plans- Exigencesetguidage Reference number ISO 28001:2007(E) @ISO 2007 by IHS under I without license from IHS Not for Resale ISO 28001:2007(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobe's licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobe's licensing policy. The IsO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by IsO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT @ISO2007 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, IsO's member body in the country of the requester. ISO copyright office Case postale 56 . CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail [email protected] Web www.iso.org Published in Switzerland @ IS0 2007 - All rights reserved Tby IHS unde I without license from IHS Not for Resale ISO 28001:2007(E) Contents Page Foreword. iv Introduction 1 Scope 2 Normative references . 3 Terms and definitions.. 4 Field of application . 4.1 Statement of application ... 4.2 Business partners... 4.3 Internationallyaccepted certificatesorapprovals... 4.4 Business partners exempt from security declaration requirement... 4.5 Security reviews of business partners........... 5 Supply chain security process. 5.1 General......... 5.2 Identification of the scope of security assessment 5.3 Conduction of the security assessment.... 5.4 Development of the supply chain security plan .... 5.5 Execution of the supply chain security plan .... 5.6 Documentation and monitoring of the supply chain security process.. 8 5.7 Actions required after a security incident.... 5.8 Protection of the security information..... Annex A (informative) Supply chain security process. 10 A.1 10 A.2 Identification of the scope of the security assessment...... 10 A.3 Conduction of the security assessment.... A.4 Development of the security plan ...... 15 A.5 Execution of the security plan.... 17 A.6 Documentation and monitoring of the security process.. 17 A.7 Continual improvement.... Annex B (informative) Methodology for security risk assessment and development of countermeasures.... 18 B.1 General... .18 B.2 Step one - Consideration of the security threat scenarios.... 20 B.3 Step two -- Classification of consequences.... 22 B.4 Step three -- Classification of likelihood of security incidents .... B.5 Step four - Security incident scoring.... B.6 Step five - Development of countermeasures 24 B.7 Step six -- impiementation of countermeasures ...... B.8 Stepseven-Evaluationofcountermeasures.. 25 B.9 Step eight - Repetition of the process ... 25 B.10 Continuation of the process .. 25 Annex C (informative) Guidance for obtaining advice and certification . .26 C.1 General...... C.2 DemonstratingconformancewithisO28001byaudit. .26 C.3 Certification of IsO 28001 by third party certification bodies.... 26 Bibliography ... Copyrght International Organizaionsandardizalonghts reserved il

.pdf文档 ISO 28001 2007 Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance

文档预览
中文文档 34 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共34页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
ISO 28001 2007 Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance 第 1 页 ISO 28001 2007 Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance 第 2 页 ISO 28001 2007 Security management systems for the supply chain — Best practices for implementing supply chain security, assessments and plans — Requirements and guidance 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2026-03-07 18:07:08上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。